Courseiva
Cryptography Application →easyMultiple Choice

GSEC Cryptography Application Practice Question

A security administrator is configuring a VPN concentrator to protect data in transit. The requirement is that each VPN session use a unique symmetric key, and that compromise of one session key never reveal another session's key or the long-term authentication secret. Which property must the key exchange provide?

⚠ Common exam trap

Many exam-takers confuse confidentiality of the handshake with forward secrecy, assuming any encrypted key exchange prevents one compromised session key from affecting others when only ephemeral, discarded secrets do.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perfect forward secrecy, so that each session key is derived independently and compromise of one does not expose others or the long-term secret.

Perfect forward secrecy uses ephemeral key agreement such as Diffie-Hellman with per-session values, so the long-term authentication secret never encrypts session keys directly. Even if one session key is later compromised, the ephemeral secrets needed to derive other sessions have been erased, and the long-term secret remains protected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Key encapsulation, so that the long-term secret directly encrypts each session key and guarantees confidentiality of the exchange.

    Why it's wrong here

    Key encapsulation typically wraps a session key with a long-term public key; if the corresponding long-term private key is later compromised, every wrapped session key can be recovered. That directly violates the requirement that compromise of one session key never reveal another session's key or the long-term secret.

  • ✗

    Collision resistance, so that two different sessions cannot produce the same derived key material during the handshake.

    Why it's wrong here

    Collision resistance is a hash function property that prevents two distinct inputs producing the same digest; it does not prevent a compromised long-term secret from unwrapping stored session keys. It is unrelated to isolating session keys from each other or protecting the long-term authentication secret.

  • ✓

    Perfect forward secrecy, so that each session key is derived independently and compromise of one does not expose others or the long-term secret.

    Why this is correct

    Perfect forward secrecy derives each session key from ephemeral values that are discarded after the exchange, so a later compromise of a session key or long-term secret cannot reconstruct other sessions' keys. This directly satisfies the requirement that no session key reveal another or the long-term authentication secret.

  • ✗

    Non-repudiation, so that each VPN endpoint can prove it participated in the session and cannot deny sending traffic.

    Why it's wrong here

    Non-repudiation is a property of digital signatures that binds a party to a message; it does not isolate session keys from one another. It addresses accountability rather than the confidentiality requirement that one session key compromise cannot expose other keys or the long-term authentication secret.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.